Medium severity6.5NVD Advisory· Published Sep 29, 2023· Updated Jun 17, 2026
CVE-2023-3413
CVE-2023-3413
Description
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.2,<16.2.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.2,<16.2.8
- cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.2
- (no CPE)range: 16.2 <= v < 16.2.8, 16.3 <= v < 16.3.5, 16.4 <= v < 16.4.1
- Range: 16.2 <= v < 16.2.8, 16.3 <= v < 16.3.5, 16.4 <= v < 16.4.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/416284nvdBroken Link
- hackerone.com/reports/2027967nvdPermissions Required
News mentions
1- GitLab Security Release: 16.4.1, 16.3.5, and 16.2.8GitLab Security Releases · Sep 28, 2023